[01.gif] [02.gif] [t4.jpg] NSFOCUS Security Advisory(SA2000-04) Topic£ºMicrosoft Win9x client driver type comparing vulnerability Release Date£º August 20, 2000 Affected System: ================ - Microsoft Windows 95 - Microsoft Windows 98 - Microsoft Windows 98 Second Edition Non-affected system£º =================== - Microsoft Windows NT - Microsoft Windows 2000 Impact: ========= NSFOCUS security team has found a security flaw in Microsoft Win9x NETBIOS client. Exploitation of this vulnerability, a malicious attacker can modify his host file share service and perform DoS attack to a Win9x client that visits it. Description£º ============ When Win9x client accessing NETBIOS file shared services and comparing the driver types, if the returned type from server is none of below:"£¿£¿£¿£¿£¿"," A£º"," LPT1£º"," COMM"or"IPC"£¬it will lead to the sixth result, which is fake cause there are only five of them. So, win9x client will get a wrong driver pointer from conversion, transfer the control to the wrong driver function address and finally crash. Workaround: ==================== Don't access the untrusted host's file share service. Microsoft has been informed. DISCLAIMS: ========== THE INFORMATION PROVIDED IS RELEASED BY NSFOCUS "AS IS" WITHOUT WARRANTY OF ANY KIND. NSFOCUS DISCLAIMS ALL WARRANTIES, EITHER EXPRESS OR IMPLIED, EXCEPT FOR THE WARRANTIES OF MERCHANTABILITY. IN NO EVENTSHALL NSFOCUS BE LIABLE FOR ANY DAMAGES WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL,CONSEQUENTIAL, LOSS OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF NSFOCUS HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. DISTRIBUTION OR REPRODUTION OF THE INFORMATION IS PROVIDED THAT THE ADVISORY IS NOT MODIFIED IN ANY WAY. ©Copyright 1999-2000 NSFOCUS. All Rights Reserved. Terms of use. NSFOCUS Security Team NSFOCUS INFORMATION TECHNOLOGY CO.,LTD (http://www.nsfocus.com) ©Copyright 2000 NSFOCUS Information Technology Co.,Ltd. All Rights Reserved. Contact:webmaster@nsfocus.com